Meet global child safety rules. Tuteliq supports KOSA, COPPA, the EU Digital Services Act, the UK Online Safety Act and the Australian Online Safety Act.

Tuteliq helps platforms meet child safety obligations across jurisdictions. Here's exactly what we cover, and how.

Quick Compliance Checklist

At a glance, the regulations and standards Tuteliq helps you address.

Regulation-by-Regulation Breakdown

Detailed coverage for each regulation, what it requires and how Tuteliq helps you comply.

KOSA. Kids Online Safety Act (pending)

KOSA is not law. It would require platforms to prevent and mitigate harms to minors, including bullying, exploitation, and promotion of self-harm, but the text is still moving between the House and the Senate. Treat this as readiness work, not compliance.

HOW TUTELIQ HELPS

  • Real-time detection of grooming, bullying, self-harm, and unsafe content across 7 risk categories
  • Age-appropriate design tooling via API-driven risk scoring
  • Parental notification support through configurable webhooks
  • Audit-ready incident logs with full traceability
  • 1.1-1.5s typical response times for proactive, not reactive, moderation
  • Coverage that already satisfies obligations in force today under the DSA, the UK Online Safety Act, COPPA and the state design codes

COPPA. Children's Online Privacy Protection Act

COPPA regulates the collection and use of personal information from children under 13, requiring verifiable parental consent and data minimization.

  • No child PII stored. Tuteliq analyses text content, not identities
  • Data minimization by design: only message content is processed, never stored beyond analysis
  • Configurable data retention and deletion via API
  • Parental control hooks for consent workflows
  • Full DPA available for COPPA-aligned data processing

EU Digital Services Act (DSA)

The DSA imposes obligations on platforms to protect users, especially minors, from illegal and harmful content, with transparency reporting and swift content actioning.

  • Automated content classification aligned with DSA illegal content categories
  • Transparency-ready: every API call returns structured risk assessments with confidence scores
  • Incident reporting with timestamps and audit trails for DSA Article 16 notices
  • Systematic risk assessment support (DSA Article 34) via aggregated analytics
  • Content moderation evidence for trusted flagger and law enforcement cooperation

UK Online Safety Act

The UK OSA requires platforms to conduct risk assessments and implement safety measures to protect children from harmful content, with Ofcom as the regulator.

  • Risk assessment evidence through structured incident classification
  • Proactive content scanning covering all priority harmful content categories for children
  • Age estimation support and age-appropriate content filtering
  • Record-keeping and compliance evidence generation
  • Rapid response: detection and alerting within milliseconds of content submission

GDPR & UK GDPR

GDPR governs how personal data is collected, processed, and stored, with strict requirements for lawful processing, data subject rights, and cross-border transfers.

  • EU-based infrastructure, data never leaves the EU
  • Privacy by design: no PII storage, content analysed in-memory only
  • Full Data Processing Agreement (DPA) available
  • Data subject access request (DSAR) support
  • Right to erasure: no persistent data to delete
  • Lawful basis documentation and processing records

AADC. Age Appropriate Design Code

The AADC (also known as the Children's Code) requires services likely to be accessed by children to provide age-appropriate experiences with high privacy defaults.

  • Risk-scored content analysis to enforce age-appropriate experiences
  • Default-high privacy: no profiling, no data retention
  • Best-interests assessment support through structured risk categories
  • Nudge and dark-pattern detection aligned with AADC principles
  • Configurable sensitivity thresholds per age group

Security & Certifications

Enterprise-grade infrastructure you can trust.

GDPR Compliant

Built to meet EU and UK data protection requirements.

EU Data Residency

All data processed and stored within EU borders. No transatlantic transfers.

Zero content retention

No evaluation content is ever stored. Fully stateless, privacy-first architecture.

End-to-End Encryption

AES-256-GCM encryption for all sensitive data in transit and at rest.

99.99% Uptime SLA

Enterprise-grade availability with redundancy and failover.

How to prepare your platform for child safety regulation

A five-step path to evidencing child safety duties under the UK Online Safety Act, the EU Digital Services Act, COPPA, and GDPR.

  • 1 Run a children's risk assessment Document which harms your service can expose children to, how likely they are, and what mitigations exist today. This assessment is the record regulators ask for first.

Run a children's risk assessment

Document which harms your service can expose children to, how likely they are, and what mitigations exist today. This assessment is the record regulators ask for first.

  • 2 Determine which duties apply Establish where your users are and whether children can access your service, then map the applicable frameworks: UK Online Safety Act, EU Digital Services Act, COPPA, GDPR and Article 8, and any state-level requirements.

Determine which duties apply

Establish where your users are and whether children can access your service, then map the applicable frameworks: UK Online Safety Act, EU Digital Services Act, COPPA, GDPR and Article 8, and any state-level requirements.

  • 3 Put proportionate detection in place Deploy detection for the harms your risk assessment identified, with thresholds calibrated to the ages of your users, and age assurance where a duty requires it.

Put proportionate detection in place

Deploy detection for the harms your risk assessment identified, with thresholds calibrated to the ages of your users, and age assurance where a duty requires it.

  • 4 Define reporting and escalation Set out who reviews flagged content, how users report harm, how quickly you respond, and when law enforcement or a hotline is notified.

Define reporting and escalation

Set out who reviews flagged content, how users report harm, how quickly you respond, and when law enforcement or a hotline is notified.

  • 5 Keep audit-ready evidence Retain incident logs, audit trails, your data processing agreement, the subprocessor list, and transparency reporting so your measures can be evidenced on request.

Keep audit-ready evidence

Retain incident logs, audit trails, your data processing agreement, the subprocessor list, and transparency reporting so your measures can be evidenced on request.

Frequently asked questions

Need a Compliance Deep-Dive?

Our team can walk you through how Tuteliq maps to your specific regulatory requirements. We also provide custom DPAs, security questionnaires, and compliance documentation.

Request a demo or compliance assessment

Tell us about your platform and we will map Tuteliq to your compliance duties within one business day.

By submitting, you agree to be contacted by Tuteliq about this request. We do not share your details with third parties.

Global Regulatory Compliance

Tuteliq helps platforms meet child safety obligations across multiple jurisdictions with a single SDK integration.

Get Started Free · Read Documentation · View Pricing